AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesHard
A global media company uses AWS Organizations to manage over 100 AWS accounts. They need to ensure that all S3 buckets across all accounts enforce encryption at rest for newly uploaded objects, regardless of the individual account configurations. Which AWS Organizations feature should be used to centrally enforce this security control?
- AAWS Config rules with Conformance Packs
- BIAM Policies attached to Organizational Units (OUs)
- CAWS Resource Access Manager (RAM)
- DService Control Policies (SCPs)
Show answer & explanationAnswer & explanation
Correct answer: D. Service Control Policies (SCPs)
Service Control Policies (SCPs) allow you to centrally manage permissions across your AWS Organization, acting as guardrails that prevent accounts from performing specified actions, even if an IAM policy grants them permission. They are ideal for enforcing mandatory controls like S3 encryption across all accounts.
Why the other options are wrong
- A. AWS Config rules are for auditing compliance and detecting non-compliant resources, not for preventing actions from occurring. Conformance Packs automate the deployment of Config rules across accounts.
- B. IAM policies are for granting permissions within a single account. They cannot override or restrict permissions across an entire organization or OUs in the same way an SCP can.
- C. AWS Resource Access Manager (RAM) is used for sharing AWS resources between accounts, not for enforcing preventive security controls across an organization.
AWS Organizations SCPs
Service Control Policies (SCPs) are a type of policy that you can use to manage permissions in your organization. SCPs offer central control over the maximum available permissions for all accounts in your organization or in specific organizational units (OUs).
- Act as guardrails, defining maximum permissions.
- Apply to all IAM users and roles in affected accounts, including the root user.
- Cannot grant permissions, only restrict them.
- Are preventive controls.
Memory trick: SCPs Guard Organizational Access, Preventing Policy Breaches.